Impact
A vulnerability in the Bulk Job Launch API (POST /api/v2/bulk/job_launch/) causes the system to authorize requested instance_groups using only a read‑level permission check. The standard single‑job launch path requires use‑level permission on the same field. As a result, a principal that has read permission—such as the built‑in System Auditor role—combined with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, effectively bypassing execution‑placement isolation.
Affected Systems
The flaw impacts Red Hat Ansible Automation Platform 2. All deployments of this product that have not applied the vendor‑provided fix for CVE‑2026‑84470 are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity. No EPSS score is available, so the exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. An attacker who can authenticate to the API with the appropriate roles can launch bulk jobs onto unauthorized instance groups, potentially leading to unintended workload execution or resource misuse.
OpenCVE Enrichment